Responsible Disclosure Policy
NOTEDFIRST SEEN 2026-08-20 · VERSION 20260820_rev01 · COMPARED WITH 20260819_rev01
What changed, in plain language
The only change is a new scrambled version of the same email address link (Cloudflare's email-protection encoding). No policy terms changed.
This change appears to be cosmetic (formatting, typos, or contact details).
Changelog
- ± CHANGEDContact email link re-encoded
The security contact link now uses a different scrambled code. This is just how the site hides the email address from spam bots — the address itself and everything else in the policy stayed the same.
https://www.theatlantic.com/cdn-cgi/l/email-protection#1b687e786e69726f625b6f737e7a6f777a756f727835787476
https://www.theatlantic.com/cdn-cgi/l/email-protection#780b1d1b0d0a110c01380c101d190c1419160c111b561b1715
Full text changes — 20260819_rev01 to 20260820_rev01
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 17 | 17 | · Spamming |
| 18 | 18 | |
| 19 | 19 | · Social engineering (including phishing) of Atlantic Media staff or contractors |
| 20 | 20 | |
| 21 | 21 | · Any physical attempts against Atlantic Media property or data centers |
| 22 | 22 | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#1b687e786e69726f625b6f737e7a6f777a756f727835787476) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! | |
| 23 | While we currently do not have a formal vulnerability reporting system in place at this time, please reach out to [\[email protected\]](https://www.theatlantic.com/cdn-cgi/l/email-protection#780b1d1b0d0a110c01380c101d190c1419160c111b561b1715) to report any critical issues you may discover. Thank you for helping keep The Atlantic and our users safe! |